Configure the JMeter SSL Manager miscellaneous features: properties, defaults, and practical usage notes for building reliable load tests.
Part of the Miscellaneous Features category. Also documented in context in the full Component Reference.
The SSL Manager is a way to select a client certificate so that you can test applications that use Public Key Infrastructure (PKI). It is only needed if you have not set up the appropriate System properties.
Choosing a Client Certificate
You may either use a Java Key Store (JKS) format key store, or a Public Key Certificate Standard #12 (PKCS12) file for your client certificates. There is a feature of the JSSE libraries that require you to have at least a six character password on your key (at least for the keytool utility that comes with your JDK).
To select the client certificate, choose Options โ SSL Manager from the menu bar.
You will be presented with a file finder that looks for PKCS12 files by default.
Your PKCS12 file must have the extension โ.p12โ for SSL Manager to recognize it
as a PKCS12 file. Any other file will be treated like an average JKS key store.
If JSSE is correctly installed, you will be prompted for the password. The text
box does not hide the characters you type at this point โ so make sure no one is
looking over your shoulder. The current implementation assumes that the password
for the keystore is also the password for the private key of the client you want
to authenticate as.
Or you can set the appropriate System properties - see the system.properties file.
The next time you run your test, the SSL Manager will examine your key store to see if it has at least one key available to it. If there is only one key, SSL Manager will select it for you. If there is more than one key, it currently selects the first key. There is currently no way to select other entries in the keystore, so the desired key must be the first.
Things to Look Out For
You must have your Certificate Authority (CA) certificate installed properly
if it is not signed by one of the five CA certificates that ships with your
JDK. One method to install it is to import your CA certificate into a JKS
file, and name the JKS file โjssecacertsโ. Place the file in your JREโs
lib/security folder. This file will be read before the โcacertsโ file in
the same directory. Keep in mind that as long as the โjssecacertsโ file
exists, the certificates installed in โcacertsโ will not be used. This may
cause problems for you. If you donโt mind importing your CA certificate into
the โcacertsโ file, then you can authenticate against all of the CA certificates
installed.